R E L A T E D   C O N T E N T
ADVERTISEMENT

UK Government was warned on data loss

Risk assessment raised concern about junior staff access in 2004

Matt Chapman, vnunet.com 10 Dec 2007
ADVERTISEMENT

The UK Government was warned that allowing junior staff to access the child benefit database was a security risk three years before discs containing 25 million records were lost.

Treasury risk manager Richard Fennelly carried out the assessment in March 2004 and sent a letter warning of weak procedures to the Treasury.

That revelation will cause embarrassment for current Prime Minister Gordon Brown, who was Chancellor of the Exchequer at the time.

"Fraudulent/malicious activity was not being detected," said a copy of Fennelly's comments obtained by the News of the World.

"Live support staff had root access and could do anything without being detected with obvious risks."

Fennelly also warned that there was "no encryption between certain elements in the system".

Shadow work and pensions secretary Chris Grayling said the document rubbished Gordon Brown's claims in Parliament that the data breach was a one-off incident.

"Now we know that internal watchdogs in the government were warning three years ago that the child benefit database was at risk," he told the News of the World.

"Because no one took any action we now face a situation where millions of bank account details and information about all our children has been lost."

HM Revenue and Customs (HMRC) lost discs containing the child benefit records of 25 million people, including the bank details of 7.25 million families, when it sent the unencrypted data through the regular postal service.

Information Minister Richard Thomas has warned that other damaging data loss incidents could emerge, as several public bodies have secretly admitted to losing data following the HMRC crisis.

See also:

Managing risk is biggest driver behind security strategies  10 Dec 2007
Greatly increased threat to UK business  06 Dec 2007
Information on 8.5 million customers on sale for five years  05 Dec 2007
As little as £1 buys you an active bank account  03 Dec 2007
Companies know there is a problem, claims SanDisk  15 Nov 2007

All Public Sector IT

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
| JAM Recruitment
Background A fantastic opportunity has just arisen within this growing multinational organisation. Working as an EMEA Advisory Consultant your main duties and responsibilities will be to provide advice and support to international organisations looking to ... more >
| Aston Carter
This is a hands-on development team lead position that will push you to the limit of your architectural and mentoring capabilities. Technical amp; development (Agile) • Create effective data solutions, in partnership with the relevant ... more >
| Aston Carter
C++ Research Developer Global Pharmaceutical Company London C++ Research Developer Biotechology Global Medical Company London Global Biotechnology Company specialising in the research and development of cutting edge health care products is looking for an innovative, ... more >
| Computer People
Junior Network Operations Engineer – Borehamwood - £24k Junior / entry level network operations engineer required, will be responsible for supporting external clients network and security solutions. Excellent entry level position as my client offers ... more >
More job opportunities